Legal
Privacy policy
What OSS Graveyard collects, why, how long we keep it, and how to get it removed.
Last updated
OSS Graveyard (“we”, “the site”) is a community catalogue of dormant open-source projects at ossgraveyard.dev. This policy covers the website and its sign-in. Browsing does not require an account.
What we collect
| Data | When | Why |
|---|---|---|
| Email address and a password hash | You create an email account | Sign-in, account recovery. The password is hashed and stored by Amazon Cognito; we never store or log it. |
| Forge account id, username and verified email | You sign in with GitHub, GitLab, Bitbucket or Codeberg | Sign-in. We request read-only access to your public profile and email, and do not keep the provider's access token. |
| Display name | Your account | Shown publicly next to your submissions. You can change it on your account page. |
| Submissions, reports and correction suggestions | You submit them | Running the catalogue. Approved submissions are public, together with your display name. |
| Messages sent with the contact form | You send one | Answering you. The reply email you enter (or your account email) is stored with the message. |
| Session cookie | While signed in | Keeping you signed in. Expires after 30 days or when you sign out. |
| Server logs | Every request | Security, abuse prevention and debugging. Logs include request details such as the path, time and your user id when signed in. |
| Usage analytics | Only if you accept analytics cookies | Google Analytics 4 helps us understand which pages are used. It sets cookies and processes your IP address and browser details. It is not loaded at all unless you choose “Accept” in the cookie banner, and you can change your mind at any time with “Cookie settings” in the footer. The site works the same without it. |
We do not sell personal data, show ads, or use your data for anything other than running the site. Your email address is never shown publicly.
Cookies
og_sid: your session (strictly necessary).og_oauth,og_pending,og_mfa: short-lived sign-in state, deleted within an hour (strictly necessary).- Your theme and cookie choices, stored in your browser's local storage (
theme,analytics-consent). The cookie choice is asked again after 12 months. - Google Analytics cookies (
_ga,_ga_*), only after you accept. Declining later deletes them.
Where data is stored and who processes it
- Amazon Web Services hosts the site, database, sign-in (Cognito) and logs in AWS us-east-1 (N. Virginia, USA).
- GitHub, GitLab, Bitbucket, Codeberg: only if you choose to sign in with them. We also call their public APIs to show repository statistics; that involves no personal data about you.
- Google for analytics, only if you accept, as described above.
How long we keep it
- Account data: until you delete your account.
- Sessions: 30 days at most.
- Server logs: up to 90 days.
- Public catalogue entries you submitted stay after account deletion, but are anonymised (shown as “Deleted user”). They are factual information about public software projects.
- Contact messages and reports: as long as needed to handle them.
Your choices and rights
- Access and portability: download a copy of your data from your account page.
- Correction: change your display name on your account page.
- Deletion: delete your account from your account page. This removes your profile, sign-in methods, sessions, password account and reports, and anonymises your submissions. It happens immediately.
- For anything else, including objections or questions, contact us. Depending on where you live, you may also have the right to complain to a data protection authority.
Children
The site is not directed at children under 13, and they may not create an account.
Changes
We will update the date at the top when this policy changes, and announce significant changes on the site.